SureCash is a product of One Rectangle Limited. SureCash is not a lender and is not currently authorised or regulated by the Financial Conduct Authority (FCA) yet. Credit is provided by Fint Limited, not by SureCash or One Rectangle Limited.
1. Who we are
The data controller for personal data collected through SureCash is One Rectangle Limited, the company behind SureCash, registered at 82a James Carter Road, Mildenhall, Bury St Edmunds, IP28 7DE.
For loan underwriting, funding decisions, and servicing, we share data with Fint Limited, who acts as a separate controller and/or processor for the purposes described in your credit agreement and their privacy notice.
ICO registration reference: ZB000000. Contact: hello@surecash.co.uk
2. What data we collect
Depending on how you use our services, we may collect:
- Identity data: full name, date of birth, address;
- Contact data: email address, telephone number;
- Financial data: employment status, employer, annual income, loan purpose;
- Application data: loan amount, term, APR offered, application status;
- Technical data: IP address, browser type, device information, cookies;
- Communications: messages you send us via contact forms or email;
- Open Banking data: where you consent, transaction data via regulated Open Banking providers under UK financial services law.
3. How we use your data and lawful bases
We process personal data under UK GDPR on the following bases:
- Contract (Article 6(1)(b)): to process your loan application, manage your account, and introduce you to Fint Limited;
- Legal obligation (Article 6(1)(c)): to comply with applicable financial services, anti-money laundering, and tax or regulatory reporting requirements;
- Legitimate interests (Article 6(1)(f)): to improve our website, prevent fraud, and analyse usage (balanced against your rights);
- Consent (Article 6(1)(a)): for non-essential cookies and certain marketing communications, where required.
4. Sharing your data
We may share your data with:
- Fint Limited and its underwriting, identity verification, and servicing partners;
- Supabase and other cloud infrastructure providers (data stored in secure environments);
- Professional advisers (lawyers, accountants) where necessary;
- Regulators, courts, or law enforcement where required by law.
We do not sell your personal data to third parties. We do not store raw bank login credentials. Open Banking connections are read-only and handled through regulated providers.
5. International transfers
We aim to keep personal data within the United Kingdom and European Economic Area. If data is transferred outside the UK/EEA, we ensure appropriate safeguards (such as UK International Data Transfer Agreements or adequacy regulations) are in place.
6. How long we keep your data
We retain application data for as long as necessary to process your request and for up to six years thereafter where required for regulatory, legal, or accounting purposes. Active loan records are retained in line with Fint Limited's retention schedule once a loan is funded.
7. Your rights
Under UK GDPR you have the right to:
- Access a copy of your personal data;
- Rectify inaccurate data;
- Erase data in certain circumstances;
- Restrict or object to processing in certain circumstances;
- Data portability where processing is based on consent or contract and carried out by automated means;
- Withdraw consent at any time (without affecting prior lawful processing);
- Lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
To exercise your rights, email hello@surecash.co.uk. We will respond within one month unless an extension is permitted.
8. Security
We use encryption in transit (TLS), access controls, and secure hosting. No method of transmission over the internet is completely secure; we cannot guarantee absolute security but we take appropriate technical and organisational measures.
9. Automated decision-making
Credit decisions may involve automated processing by Fint Limited. You have the right to request human intervention, express your point of view, and contest a decision where applicable under UK GDPR Article 22.
10. Children
Our services are not directed at anyone under 18. We do not knowingly collect data from children.
11. Changes
We may update this policy from time to time. Significant changes will be posted on this page. For complaints about data handling, contact complaints@surecash.co.uk or see our complaints procedure.